Microsoft Windows 11 22H2 vulnerabilities
1,432 known vulnerabilities affecting microsoft/windows_11_22h2.
Total CVEs
1,432
CISA KEV
67
actively exploited
Public exploits
43
Exploited in wild
75
Severity breakdown
CRITICAL39HIGH1001MEDIUM387LOW5
Vulnerabilities
Page 8 of 72
CVE-2023-35367P2CRITICALCVSS 9.8fixed in 10.0.22621.19922023-07-11
CVE-2023-35367 [CRITICAL] CWE-20 CVE-2023-35367: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-23392P2CRITICALCVSS 9.8fixed in 10.0.22000.14132023-03-14
CVE-2023-23392 [CRITICAL] CWE-416 CVE-2023-23392: HTTP Protocol Stack Remote Code Execution Vulnerability
HTTP Protocol Stack Remote Code Execution Vulnerability
nvd
CVE-2023-36911P2CRITICALCVSS 9.8fixed in 10.0.22621.21342023-08-08
CVE-2023-36911 [CRITICAL] CWE-190 CVE-2023-36911: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-26670P2HIGHCVSS 8.1fixed in 10.0.22621.51892025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-36606P3HIGHCVSS 7.5fixed in 10.0.22621.24282023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-30017P2HIGHCVSS 8.8fixed in 10.0.22621.35932024-05-14
CVE-2024-30017 [HIGH] CWE-122 CVE-2024-30017: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2024-38104P2HIGHCVSS 8.8fixed in 10.0.22621.38802024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-38116P2HIGHCVSS 8.8fixed in 10.0.22621.40372024-08-13
CVE-2024-38116 [HIGH] CWE-122 CVE-2024-38116: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-49080P2HIGHCVSS 8.8fixed in 10.0.22621.46022024-12-12
CVE-2024-49080 [HIGH] CWE-122 CVE-2024-49080: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2025-21376P3HIGHCVSS 8.1fixed in 10.0.22621.48902025-02-11
CVE-2025-21376 [HIGH] CWE-122 CVE-2025-21376: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-28220P3HIGHCVSS 8.1fixed in 10.0.22621.15552023-04-11
CVE-2023-28220 [HIGH] CWE-591 CVE-2023-28220: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-28219P3HIGHCVSS 8.1fixed in 10.0.22621.15552023-04-11
CVE-2023-28219 [HIGH] CWE-591 CVE-2023-28219: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-49708P3CRITICALCVSS 9.9fixed in 10.0.22621.60602025-10-14
CVE-2025-49708 [CRITICAL] CWE-416 CVE-2025-49708: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges o
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-21708P2CRITICALCVSS 9.8fixed in 10.0.22000.14132023-03-14
CVE-2023-21708 [CRITICAL] CWE-191 CVE-2023-21708: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2024-43452P3HIGHCVSS 7.5fixed in 10.0.22621.44602024-11-12
CVE-2024-43452 [HIGH] CWE-367 CVE-2024-43452: Windows Registry Elevation of Privilege Vulnerability
Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2024-30078P3HIGHCVSS 8.8fixed in 10.0.22621.37372024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2025-33070P3HIGHCVSS 8.1fixed in 10.0.22621.54722025-06-10
CVE-2025-33070 [HIGH] CWE-908 CVE-2025-33070: Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privile
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2024-38240P3CRITICALCVSS 9.8fixed in 10.0.22621.41692024-09-10
CVE-2024-38240 [CRITICAL] CWE-125 CVE-2024-38240: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2025-26645P3HIGHCVSS 8.8fixed in 10.0.22621.50392025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-53722P3HIGHCVSS 7.5fixed in 10.0.22621.57682025-08-12
CVE-2025-53722 [HIGH] CWE-400 CVE-2025-53722: Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.
nvd